Shoppable Images (Lookbook) for WooCommerce <= 1.3 - Missing Authorization
medium
The Shoppable Images (Lookbook) for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3
- Fixed in:
- 1.3.1
- Disclosed:
- Jun 26, 2026
CVE-2026-57649 on NVD →
Shoppable Images [mabel-shoppable-images-lite] < 1.2.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- May 18, 2023
CVE-2023-25698 on NVD →
Shoppable Images Lite <= 1.2.3 - Missing Authorization
medium
The Shoppable Images Liteplugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on several functions used to manipulate images. This makes it possible for unauthenticated attackers to perform im...
- CVSS:
- 6.3
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 13, 2023
Shoppable Images <= 1.2.3 - Cross Site Request Forgery
medium
The Shoppable Images plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on several functions used to manipulate images. This makes it possible for unauthenticated attackers to perform image manipulation tasks suc...
- CVSS:
- 5.4
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 13, 2023
CVE-2023-25698 on NVD →
Shoppable Images [mabel-shoppable-images-lite] < 1.0.1
unknown
WordPress Shoppable Images Lite plugin Cross-Site Request Forgery (CSRF)/PHP Object Injection Vulnerabilities were found in the show_admin_notices function. The value of $_GET nonce variable is unserialized, which allows PHP object injection.<br />
Update the plugin.<br />
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Sep 25, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database